# 静态站点配置模板
server {
    listen 443 ssl;
    server_name {{DOMAIN}};
    
    # SSL 证书配置
    ssl_certificate /etc/nginx/sites/{{SITE_NAME}}/ssl/cert.crt;
    ssl_certificate_key /etc/nginx/sites/{{SITE_NAME}}/ssl/private.key;
    
    # SSL 安全配置
    ssl_protocols TLSv1.2 TLSv1.3;
    ssl_ciphers ECDHE-RSA-AES256-GCM-SHA512:DHE-RSA-AES256-GCM-SHA512;
    ssl_prefer_server_ciphers off;
    
    # 安全头
    add_header Strict-Transport-Security "max-age=63072000" always;
    add_header X-Frame-Options SAMEORIGIN always;
    add_header X-Content-Type-Options nosniff always;
    
    # 静态文件服务
    location / {
        root /etc/nginx/sites/{{SITE_NAME}}/www;
        index index.html index.htm;
        try_files $uri $uri/ =404;
    }
    
    # 错误页面
    error_page 404 /404.html;
    error_page 500 502 503 504 /50x.html;
    
    # 静态资源缓存
    location ~* \.(jpg|jpeg|png|gif|ico|css|js)$ {
        expires 1y;
        add_header Cache-Control "public, immutable";
    }
}